Every artefact behind this page, graded. There is no engineering-blog, talk
or paper tier here, because the hunt could not reach those hosts; what follows is code,
decision records, advisories and vendor documentation.
Postmortem
Open Container Initiative2019-02
runc advisory: host binary overwrite via /proc/self/exe (CVE-2019-5736)
The first widely exploited escape in this stack. A container with root could overwrite the host runc binary through mishandled file-descriptor semantics, either from a hostile image or through an exec into a container it already controlled.
Carry forwardPut a second isolation boundary under untrusted workloads; the namespace boundary has been escapable in every year since.
https://github.com/advisories/GHSA-gxmr-w5mj-v8hh
Postmortem
Open Container Initiative2024-01
runc advisory: container breakouts due to internally leaked fds (CVE-2024-21626)
Descriptors leaked into runc init, including a handle to the host cgroup filesystem, plus a missing check that the working directory stayed inside the mount namespace.
Carry forwardEnumerate what crosses every fork and exec you introduce; it is attack surface the interface definition does not describe.
https://github.com/opencontainers/runc/security/advisories/GHSA-xr7r-f8xq-vfvv
Postmortem
Open Container Initiative2025-11
runc advisory: escape via masked path abuse (CVE-2025-31133)
Masking with a bind mount of /dev/null was not verified to be a real /dev/null, and ENOENT was ignored, so masking of sensitive /proc entries could be bypassed. One of three High advisories published on the same day.
Carry forwardTreat a runtime’s masked-path list as a map of what attackers aim at, not as a control.
https://github.com/opencontainers/runc/security/advisories/GHSA-9493-h29p-rfm2
Postmortem
Open Container Initiative2021-2026
runc published advisories, index
Ten advisories across five years, clustering in mount and procfs handling. The index is the cheapest way to see that this is a recurring class rather than a run of unrelated bugs.
Carry forwardRead a dependency’s advisory index before its README; the pattern tells you what the design cannot protect.
https://github.com/opencontainers/runc/security/advisories
Postmortem
Docker / Moby2024-07
moby advisory: AuthZ zero length regression (CVE-2024-41110)
States in writing that the January 2019 fix “was not carried forward to later major versions, resulting in a regression” across every line from 19.03 to 27.1.0.
Carry forwardA restructure creates branch lines; audit fix containment with git tag --contains, not with release notes.
https://github.com/moby/moby/security/advisories/GHSA-v23v-6jw2-98fq
Source code
Docker / Moby2018-11
Commit 2ac8a479c5, authorization plugin fixes
The original fix. git merge-base shows it is not an ancestor of v19.03, v20.10, v23.0 or v27.1.0, and its first containing tag is v28.0.0-rc.1 in February 2025.
Carry forwardThe commit, not the changelog, is the unit of truth about whether a fix is in a release.
https://github.com/moby/moby/commit/2ac8a479c53d9b8e67c55f1e283da9d85d2b3415
Source code
Docker / Moby2024-07
Commit bed37b6152, merge from a security fork
The 2024 remediation is a merge whose second parent is the December 2018 commit: the repository itself records the six-year detour.
Carry forwardSecurity forks are branch lines too; give them an owner and a merge deadline.
https://github.com/moby/moby/commit/bed37b6152327ae67f37cebf2690b7d746b99fb6
Source code
Docker / Moby2017-04
Pull request #32691: a new upstream project to break up Docker
The restructure argued in public, including the production chain from upstream components to the commercial product, and the objection that dependent projects were given no notice.
Carry forwardAnnounce the import-path plan with the repository plan; the path outlived the rename by eight years.
https://github.com/moby/moby/pull/32691
Source code
Docker / Moby2015-2024
Pull request #13602: checkpoint and restore
Deferred in February 2016 to land after the containerd integration, kept open through the whole decomposition, closed unmerged in March 2024 with 320 comments.
Carry forwardDeferring a feature across a boundary drops it unless someone on the other side is accountable.
https://github.com/moby/moby/pull/13602
Source code
Docker / Moby2014-2024
Closed, unmerged pull requests by discussion volume
The most-argued proposals in the repository were closed rather than merged, including build-time environment variables (475 comments) and private registry mirrors, open from 2017 to 2024.
Carry forwardRead a project’s closed-unmerged queue to find the boundary its maintainers are defending.
https://github.com/moby/moby/pulls?q=is%3Apr+is%3Aclosed+is%3Aunmerged+sort%3Acomments-desc
Source code
Docker / Moby2013-2026
moby/moby repository history
Commits per year from 10,133 in 2016 to 1,065 in 2021 and back to 4,410 in 2025, with 58,195 commits and 72.1k stars at the time of reading.
Carry forwardCommit volume by year is the cheapest health signal for any dependency, and it moves a year before announcements do.
https://github.com/moby/moby
Source code
Docker / Moby2015-2025
Engine release tags
v1.12.0 in July 2016, a calendar-version experiment from February 2017, a 26-month gap after v20.10.0, an abandoned v22.06 beta, and a tag prefix change at docker-v29.0.0 in November 2025.
Carry forwardVersion schemes change when the business does; an abandoned beta line is the clearest public sign of a stalled plan.
https://github.com/moby/moby/tags
Source code
Docker / Moby2022-07
Commit 7d74269c0d, the containerd image service
The first commit of daemon/containerd, which grew to 282 commits in 2023: the product rebuilding its own storage layer on the component it had donated five years earlier.
Carry forwardAdopting your own donated component is a multi-year programme, not a switch.
https://github.com/moby/moby/commit/7d74269c0dafb71a760d8c669fca3d2df5778d2e
Source code
Docker / Moby2025-07
Commit 632de98f75, containerd snapshotters by default
The default image store becomes containerd’s, with a follow-up two months later excluding Windows.
Carry forwardDefaults move years after capability; measure adoption by the default, not by the feature flag.
https://github.com/moby/moby/commit/632de98f75dc87e0e1900097ee1177aa64c8c45d
Source code
Docker / Moby2026-06
Commit a8a1cfd111, embedded containerd mode
An experimental mode that runs containerd inside the daemon process rather than as a separately managed one: partial re-bundling of the component that was extracted in 2016.
Carry forwardRe-absorption is a legitimate late move, but name the consumers you are willing to lose first.
https://github.com/moby/moby/commit/a8a1cfd1114e7472590206f5ebb8e088beee7a1c
Source code
Docker / Moby2025-07
Commit 53bd828853, remove libnetwork
Networking, a separate repository since February 2015, is moved into daemon/libnetwork and the standalone tree is deleted, after its own commit volume had fallen to 18 in 2023.
Carry forwardA component with one consumer is a module, not a product; stop paying the boundary tax.
https://github.com/moby/moby/commit/53bd828853008b3187545849c1f2000f024861d0
Decision record
containerd2017-2026
SCOPE.md: an allow-list of responsibilities
Networking, build, logging and volume management are explicitly refused, and anything not listed is out of scope by default.
Carry forwardWrite your component’s refusals before its features; that document is what makes it adoptable by people who do not trust you.
https://raw.githubusercontent.com/containerd/containerd/main/SCOPE.md
Source code
containerd2026-09
ADOPTERS.md
Twenty-six named production adopters, including every major managed Kubernetes service, two AWS isolation platforms, k3s, Kata and the Docker engine itself as one entry among them.
Carry forwardThe adopter list is the clearest measure of whether an extraction succeeded.
https://raw.githubusercontent.com/containerd/containerd/main/ADOPTERS.md
Source code
containerd2017-2026
Release tags and commit history
v1.0.0 in December 2017, v2.0.0 in November 2024, v2.4.0 in September 2026, with commit volume between 1,355 and 3,152 a year for a decade.
Carry forwardA component that holds flat activity for ten years is a dependency you can plan around; one that spikes and falls is not.
https://github.com/containerd/containerd/tags
Decision record
Kubernetes2020-12
KEP-2221: removing dockershim from kubelet
The design record for the removal, naming the maintenance burden of a built-in dependency on one runtime, with deprecation in v1.20 and removal in v1.24.
Carry forwardA special case survives only while it is the only implementation; the second implementation is the clock starting.
https://github.com/kubernetes/enhancements/blob/master/keps/sig-node/2221-remove-dockershim/README.md
Source code
Mirantis2022-2026
cri-dockerd
The removed shim as a standalone product, carrying its original history from a 2016 commit inside Kubernetes, maintained by the company that bought Docker’s enterprise business. Commits fell to 17 so far in 2026.
Carry forwardRemoved code does not die if someone has customers; check who picked it up before assuming a migration is forced.
https://github.com/Mirantis/cri-dockerd
Source code
Open Container Initiative2017-2025
image-spec and runtime-spec tags
v1.0 in July 2017 for both, then near-silence: 8 commits in 2020 for the image spec, and six years and seven months to v1.1.0.
Carry forwardFreezing an interface is a design act with a cost and a payoff; the payoff is that both sides become replaceable.
https://github.com/opencontainers/image-spec/tags
Decision record
Docker2020-05
docker/roadmap issue #87: anti-abuse rate limits
Metering the registry begins as an abuse control at 20,000 pulls per six hours, justified by observed rates above 60,000.
Carry forwardFree infrastructure at internet scale ends as metering; plan a pull-through cache before the limit lands, not after.
https://github.com/docker/roadmap/issues/87
Decision record
Docker2020-2024
docker/roadmap issue #7: improve Mac file system performance
The most-demanded item on the public roadmap for four years was the boundary between the developer’s machine and the Linux virtual machine, closed as shipped with Desktop 4.27 in February 2024.
Carry forwardWhen a product loses the server layer, its remaining architecture problem is the client boundary; the roadmap says so before the marketing does.
https://github.com/docker/roadmap/issues/7
Vendor doc
Docker2026-09
Docker Hub pull limits
100 pulls per six hours per address or /64 subnet unauthenticated, 200 for a free account, unlimited on paid plans.
Carry forwardBudget CI image pulls per identity, and authenticate CI even when you are on the free tier.
https://raw.githubusercontent.com/docker/docs/main/content/manuals/docker-hub/usage/pulls.md
Vendor doc
Docker2026-09
Docker Desktop licence terms
Free below 250 employees and $10M revenue, for personal use, education and non-commercial open source; paid above that.
Carry forwardA client licence change is an architecture event for everyone who standardised their onboarding on it.
https://raw.githubusercontent.com/docker/docs/main/content/manuals/subscription-billing/desktop-license.md
Vendor doc
Docker2026-09
Docker Hub official image counters
nginx at 21,498,949 pulls in the week of 14 to 20 September 2026 and over a billion in total; alpine at 25,142,478 in the same week.
Carry forwardThe registry kept its position while the runtime did not, which is what makes metering it viable.
https://hub.docker.com/_/nginx
Source code
Red Hat / containers2017-2026
podman
A competing implementation with no manager daemon and a compatible command line, 28,467 commits, and roughly 3,000 to 4,400 commits a year through the period when the engine was at its quietest.
Carry forwardThe alternative to a daemon is not a better daemon; check whether your architecture needs the long-running process at all.
https://github.com/containers/podman
Source code
abiosoft2021-09
colima
First commit on 4 September 2021, days after the Desktop subscription terms took effect; podman-desktop follows in March 2022.
Carry forwardPricing changes on developer tooling produce replacements within weeks, and their first commits are the timestamp.
https://github.com/abiosoft/colima
Case study
Kubernetes2022-11
registry.k8s.io
The project moved its image hosting to a community-controlled domain because of “significant egress traffic costs from users on other cloud providers”, so it could serve AWS users from AWS-local storage.
Carry forwardAt sufficient scale the registry becomes an egress-cost problem, and the fix is topology, not caching policy.
https://github.com/kubernetes/registry.k8s.io
Source code
GitLab2019-2026
gitlab-org/ci-cd/docker-machine
A fork carrying nine patch releases beyond the upstream tool’s final version, which has had no commit since September 2019, kept alive for CI autoscaling.
Carry forwardDepending on a vendor’s non-product component means owning a fork; price it on day one.
https://gitlab.com/gitlab-org/ci-cd/docker-machine
Source code
GitLab2026-09
gitlab-runner
A decade-old consumer still shipping the forked machine driver in 2026 while wiring Podman integration tests into CI, which is the exit path being built in public.
Carry forwardWatch what large consumers add support for; it is the earliest reliable signal of a platform shift.
https://gitlab.com/gitlab-org/gitlab-runner
Source code
Docker / Moby2025-11
Go module deprecation
The module github.com/docker/docker is deprecated from Docker v29 and replaced by github.com/moby/moby/v2, eight years after the repository was renamed.
Carry forwardImport paths are the slowest part of a rename; schedule them with the rename or expect to carry both for years.
https://pkg.go.dev/github.com/moby/moby/v2
Source code
Docker2020-06
classicswarm: commit 8653f6a, archive this project
The original standalone scheduler archived four years after the in-engine one replaced it, its commits having fallen from 1,739 in 2015 to 13 in 2020.
Carry forwardArchiving lags abandonment by years; read commit volume, not repository status.
https://github.com/docker/classicswarm/commit/8653f6a0dadbb821ee701066530d57672018c2a2
Source code
Docker / Moby2016-2026
swarmkit
From 2,601 commits in its first year to 32 in 2025, still tagged v2.1.2 in April 2026 and never archived.
Carry forwardA component can be both maintained and finished; distinguish maintenance from investment before you build on it.
https://github.com/moby/swarmkit
Decision record
Docker / Moby2018-10
ROADMAP.md and its history
The last substantive edit is titled “Update roadmap to reflect reality” and is dated 28 October 2018; later commits fix a typo and a link.
Carry forwardThe age of a published roadmap is a dependency signal, and it is free to check.
https://github.com/moby/moby/blob/master/ROADMAP.md
Source code
Docker / Moby2018-2026
buildkit
The build path as a separate, growing project: the default builder from Engine 23.0, and 1,449 commits in 2024 against the engine’s 2,657.
Carry forwardWhen the runtime commoditises, the differentiated work moves up to the build and down to the kernel.
https://github.com/moby/buildkit
Vendor doc
Docker2026-07
Python SDK for the Engine API
Still current at 7.2.0 in July 2026: the client contract is the part of the product that never broke.
Carry forwardThe API you must never break is the one with third-party clients, and it is rarely the one you are rewriting.
https://pypi.org/project/docker/